SB2016080101 - Multiple vulnerabilities in lighttpd 



SB2016080101 - Multiple vulnerabilities in lighttpd

Published: August 1, 2016 Updated: August 20, 2016

Security Bulletin ID SB2016080101
Severity
Medium
Patch available
YES
Number of vulnerabilities 3
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 33% Low 67%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 3 secuirty vulnerabilities.


1) Cross-site scripting (CVE-ID: N/A)

The vulnerability can be used by a remote attacker to perform cross-site scripting attacks.

The vulnerability is caused by incorrect filtration of input data when displaying HTML and XML output. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in victim’s browser in security context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


2) Privilege escalation (CVE-ID: N/A)

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to incorrect symlink handling in stat_cache, when “server.follow-symlink” is set to “disable”. A local attacker can overwrite arbitrary files on the target system with privileges of the web server.

Successful exploitation of this vulnerability may allow a local user to obtain elevated privileges.


3) Httpoxy issue (CVE-ID: CVE-2016-5387)

The vulnerability allows a remote attacker to obtain potentially sensitive information and compromise vulnerable server.

The vulnerability exists due to a design error in multiple implementations of web servers. A remote unauthenticated attacker can use a specially crafted Proxy header in HTTP request to influence HTTP_PROXY environment variable and redirect application’s HTTP traffic to arbitrary proxy server.

Successful exploitation of this vulnerability may allow an attacker to gain unauthorized access to sensitive information and compromise vulnerable server.

This vulnerability is known as httppoxy.


Remediation

Install update from vendor's website.